Eyes on the Prize

August 31, 2026

Fraudsters have their eyes on the prize. The route there is negotiable. Regulatory change, a less protected payment rail, an Instagram holiday photo: whatever creates an opening is fair game. For banks, that makes the challenge bigger than stopping today’s scams. Fraud strategies also need to withstand tomorrow’s pivots.


1. ThreatMark Publishes The Fraud Readiness Benchmark 2026

ThreatMark has released The Fraud Readiness Benchmark 2026, a survey of how financial institutions are preparing for evolving fraud threats, shifting reimbursement liability, and emerging attack methods. The benchmark finds a readiness gap wider than ever: two-thirds of North American banks expect APP-fraud reimbursement mandates within two years, yet only one-third feel prepared, a 38-point gap. It also reports that social engineering now touches the majority of fraud at 55% of institutions, while 83% rate behavioral intelligence the most effective defense of any tool.

For fraud teams assessing their own defenses, the benchmark shows where the industry stands on regulatory strain, human vulnerabilities, and the real-time detection approaches leading institutions are adopting. The full report includes the underlying data and best practices to inform that decision.

2. The New Cyberattack Starts with a Phone Call

Attackers targeting some of Wall Street’s biggest financial firms are borrowing a page straight from the scammer playbook: Don’t beat the security controls. Convince a legitimate user to help you through them. Google says UNC6671 targeted more than 200 organizations in roughly five weeks, calling employees on their personal phones, impersonating IT support, and directing them to fake login portals designed to capture credentials and MFA tokens.

For fraud teams, the attack exposes a familiar weakness: authentication can establish who is taking an action without establishing why. Just as an authorized scam victim can genuinely authorize a fraudulent payment under manipulation, a genuine employee can authenticate an attacker. When social engineering turns legitimate users into part of the attack path, identity alone is no longer enough.

3. Fraudsters Shift to “Hybrid” Payment Scams

In the UK, fraudsters are increasingly persuading victims to approve card payments, digital wallet transfers, and cryptocurrency transactions instead of traditional bank transfers, Which? reports. The new tactic is designed to circumvent stronger protections against APP scams that banks implemented following the UK’s reimbursement mandates—leaving many victims without the refunds they expect.

The shift shows the limits of tackling scams payment rail by payment rail: squeeze fraud in one channel, and criminals have every incentive to find another way to move the money.

4. AI Chatbot Outperformed Human Scammers in Study

A study by researchers at Northeastern University found that an AI chatbot was nearly twice as effective as human scammers in a simulated “pig butchering” scam. Over a seven-day experiment, the chatbot persuaded nearly half of participants to take a risky action, compared to about 18% for the human fraudsters.

Perhaps more concerning, only one participant identified the chatbot as AI during the interaction. Most recognized it only in hindsight after the deception was revealed—showing how difficult AI impersonation can be to recognize in the moment. The study also raises a separate question: can current AI safeguards detect long-term trust-building and social engineering designed to lay the groundwork for fraud that happens later?

5. Scammers Exploit Confusion Around New EU Crypto Rules

Criminals are exploiting the rollout of the EU’s new Markets in Crypto-Assets (MiCA) regulation. By impersonating crypto firms and regulators, they are sending fake messages urging users to move assets or provide account information. Reports of scams have increased since the rules took effect on July 1.

While MiCA aims to improve transparency and consumer protection, scammers are capitalizing on the uncertainty surrounding the transition. Customers expect to hear from providers about licensing, account transfers, and platform changes, giving fraudsters an opportunity to disguise scam messages as updates. Some regulators have even altered their approach to implementation, acknowledging that the transition itself has become a target for scammers.

6.  Jury-Duty Scams Show the Power of Keeping Victims Engaged

Authorities in Florida are reporting a rise in jury-duty scams that convince victims they’ve missed a court summons and face arrest unless they make an immediate “bail” payment. The scammers often keep targets on the phone throughout the process, preventing them from verifying the claims with family members, authorities, or other trusted contacts.

Mobile phones or landlines are used in many scams, and AI-powered voice cloning is making these interactions increasingly convincing. For fraud teams, that increases the value of signals that reveal when a customer may be under the influence of a scammer, such as active phone calls or other signs of coaching during a transaction.

7. AI Turns Holiday Photos Into Scam Material

A common “unusual account activity” scam is getting an AI upgrade. Using holiday photos posted on social media and freely available AI models, criminals can identify where victims have traveled and reference those locations in texts or emails claiming to detect suspicious account activity, adding credibility to requests for personal or banking information.

With AI, scammers don’t need photos to be tagged or contain location metadata to identify where they were taken. Details such as architecture, signage, landmarks, or even landscaping are often enough to pinpoint the location. Information that once required research can now be extracted automatically, turning everyday social media posts into reconnaissance for scam campaigns.

8. US Considers Private-Sector Hacking to Fight Cybercrime

The Trump administration is preparing a controversial program that would allow approved private companies to disrupt foreign cybercrime groups under government authorization. Participating firms could be permitted to take down criminal infrastructure or infiltrate cybercriminal systems, with each operation requiring government approval.

The proposal reflects a growing reality: despite years of arrests, takedowns, and sanctions, cybercrime continues to grow. Whether “cyber privateering” becomes part of the solution or creates new complications remains to be seen.

9. APAC Central Banks Team Up Against Digital Scams

Eleven central banks and monetary authorities across Asia-Pacific are forming a dedicated task force to strengthen information sharing on digital scams. The initiative brings together Executives’ Meeting of East Asia-Pacific Central Banks (EMEAP) members including Australia, China, Japan, Korea, the Philippines, and Singapore.

The announcement reflects a challenge many fraud teams know well: every organization sees part of the scam, but rarely the whole thing. By improving intelligence sharing across the region, the task force aims to make it harder for criminals to exploit the gaps between institutions and jurisdictions.

The staggering figures highlight the extent to which social engineering fraud has escalated into sophisticated, business-like operations for criminals—and a major transnational threat to everyone else.

10. Brazil Introduces 24-Hour Hold on High-Risk Crypto Transfers

Brazil’s central bank will require cryptocurrency exchanges to delay certain international transfers by up to 24 hours under new fraud-prevention rules. The measure targets transfers exceeding roughly $10,000 and is designed to stop fraudsters from quickly moving stolen funds beyond the reach of recovery efforts.

The move reflects a growing recognition that speed often favors criminals. By introducing friction into high-risk transactions, exchanges gain valuable time to investigate suspicious activity and intervene before funds disappear.


Banking Threat Bulletin highlights the stories shaping global fraud prevention and customer protection. Stay informed. Strengthen trust. Protect your customers.